Re: [syzbot] [overlayfs?] WARNING in ovl_listxattr

From: Edward Adam Davis
Date: Thu Jun 12 2025 - 10:45:03 EST


#syz test

diff --git a/fs/xattr.c b/fs/xattr.c
index 8ec5b0204bfd..3751c9306274 100644
--- a/fs/xattr.c
+++ b/fs/xattr.c
@@ -491,6 +491,7 @@ vfs_listxattr(struct dentry *dentry, char *list, size_t size)

if (inode->i_op->listxattr) {
error = inode->i_op->listxattr(dentry, list, size);
+ printk("buf: %s, size: %lu, res: %ld, sb: %s, %s\n", list, size, error, inode->i_sb->s_type->name, __func__);
} else {
error = security_inode_listsecurity(inode, list, size);
if (size && error > size)
@@ -1466,12 +1467,14 @@ ssize_t simple_xattr_list(struct inode *inode, struct simple_xattrs *xattrs,
int err = 0;

err = posix_acl_listxattr(inode, &buffer, &remaining_size);
+ printk("inode: %p, buf: %s, size: %lu, res: %d, remaining_size: %ld, %s\n", inode, buffer, size, err, remaining_size, __func__);
if (err)
- return err;
+ goto out;

err = security_inode_listsecurity(inode, buffer, remaining_size);
+ printk("2inode: %p, buf: %s, size: %lu, res: %d, remaining_size: %ld, %s\n", inode, buffer, size, err, remaining_size, __func__);
if (err < 0)
- return err;
+ goto out;

if (buffer) {
if (remaining_size < err)
@@ -1479,6 +1482,7 @@ ssize_t simple_xattr_list(struct inode *inode, struct simple_xattrs *xattrs,
buffer += err;
}
remaining_size -= err;
+ err = 0;

read_lock(&xattrs->lock);
for (rbp = rb_first(&xattrs->rb_root); rbp; rbp = rb_next(rbp)) {
@@ -1498,6 +1502,8 @@ ssize_t simple_xattr_list(struct inode *inode, struct simple_xattrs *xattrs,
}
read_unlock(&xattrs->lock);

+ printk("3inode: %p, buf: %s, size: %lu, res: %d, remaining_size: %ld, %s\n", inode, buffer, size, err, remaining_size, __func__);
+out:
return err ? err : size - remaining_size;
}